Repository navigation
[Extension]: Add ThreatSpec (v0.1.0) #4660
Description
Activity
- addedtriage-can-waitVerdict: valid and in-scope but deprioritized; held behind the evidence gateVerdict: valid and in-scope but deprioritized; held behind the evidence gateand removed
on Sep 21, 2026 github-actions commented
on Sep 22, 2026 on Sep 22, 2026 – with GitHub ActionsContributorMore actionscc @github/spec-kit-maintainers — new catalog submission for review.
github-actions commented
on Sep 22, 2026 on Sep 22, 2026 – with GitHub ActionsContributorMore actionsValidation failed for this submission.
- Download archive fetch: failed. The tag-pinned URL is correctly formed and matches repository
hupe1980/spec-kit-threatspecand versionv0.1.0, but the required HTTPS archive download could not be completed in the validation runner (curlwas denied permission). Because the archive was not fetched, HTTP 200 and archive validation cannot be marked passed.
The following checks passed: extension ID format, version format, repository accessibility, required
extension.yml,README.md, andLICENSEfiles, download URL repository and tag pinning, matching GitHub releasev0.1.0, and all required issue checkboxes. No catalog changes were made.Please provide a download URL that the validator can retrieve over HTTPS, then resubmit for validation.
Generated by 🧩 Add Community Extension from Issue Submission for #4660 · copilot · gpt52codex · 1.42 AIC · ⌖ 6.02 AIC · ⊞ 23K · ◷
Reacted by VETS- Download archive fetch: failed. The tag-pinned URL is correctly formed and matches repository
The download URL is the canonical GitHub tag archive:
https://github.com/hupe1980/spec-kit-threatspec/archive/refs/tags/v0.1.0.zip
The validation output confirms that the URL is correctly formed, matches the repository and v0.1.0 tag, and that the corresponding GitHub release exists. The only failed check was the archive fetch because curl was denied permission in the validation runner.
@mnriem Could you please re-run the validation? I don't believe the download URL itself needs to be changed.
github-actions commented
on Sep 23, 2026 on Sep 23, 2026 – with GitHub ActionsContributorMore actionsValidation passed for this extension submission.
- Extension ID and version formats are valid.
- The repository is publicly accessible and contains
extension.yml,README.md, andLICENSE. - The download URL is repository-owned, tag-pinned to
v0.1.0, and returned HTTP 200. - The
v0.1.0GitHub release exists. - Downloaded archive SHA-256:
6003b667e01e51a4637e4b6c2f2cea644674449f5bd2e7ed9301d3459a5a9c40. - All required testing and submission checklist items are checked.
The catalog and documentation updates will be proposed in a pull request. cc @hupe1980
Generated by 🧩 Add Community Extension from Issue Submission for #4660 · copilot · gpt52codex · 3.41 AIC · ⌖ 13.6 AIC · ⊞ 23.9K · ◷
- added a commit that references this issue
on Sep 23, 2026 github-actions commented
on Sep 23, 2026 on Sep 23, 2026 – with GitHub ActionsContributorMore actionsPull request created: #4701
Generated by Add Community Extension from Issue Submission · copilot · gpt52codex · 3.41 AIC · ⌖ 13.6 AIC · ⊞ 23.9K
- added a commit that references this issue
on Sep 23, 2026
Extension ID
threatspec
Extension Name
ThreatSpec
Version
0.1.0
Description
ThreatSpec is a spec-kit extension that makes threat modeling and security traceability a first-class part of Spec-Driven Development.
Author
hupe1980
Repository URL
https://github.com/hupe1980/spec-kit-threatspec
Download URL
https://github.com/hupe1980/spec-kit-threatspec/archive/refs/tags/v0.1.0.zip
License
MIT
Homepage (optional)
https://github.com/hupe1980/spec-kit-threatspec
Documentation URL (optional)
https://github.com/hupe1980/spec-kit-threatspec/blob/main/README.md
Changelog URL (optional)
https://github.com/hupe1980/spec-kit-threatspec/blob/main/CHANGELOG.md
Required Spec Kit Version
Required Tools (optional)
Number of Commands
3
Number of Hooks (optional)
7
Tags
security, threat-modeling, llm, agentic, traceability
Key Features
threat-model.yamlfrom spec.md and plan.md, validated by a bundled JSON Schemaverifiedrequires an inspectable pointer, verification history is append-only, and gaps are appended to tasks.md as traceable tasksTesting Checklist
Submission Requirements
extension.ymlmanifest includedTesting Details
Tested on:
Test project: an internal link shortener built end to end with the full nine-step workflow, from /speckit.specify through to security convergence.
Test scenarios:
--dev,--from <archive URL>, and by name from a self-hosted catalog; confirmed .extensionignore keeps tests and docs out of the installExample Usage
Proposed Catalog Entry
{ "threatspec": { "name": "ThreatSpec — Threat Modeling & Security Traceability", "id": "threatspec", "description": "STRIDE and AI/ML threat modeling with threat-to-test traceability and security convergence", "author": "hupe1980", "version": "0.1.0", "download_url": "https://github.com/hupe1980/spec-kit-threatspec/archive/refs/tags/v0.1.0.zip", "repository": "https://github.com/hupe1980/spec-kit-threatspec", "homepage": "https://github.com/hupe1980/spec-kit-threatspec", "documentation": "https://github.com/hupe1980/spec-kit-threatspec/blob/main/README.md", "changelog": "https://github.com/hupe1980/spec-kit-threatspec/blob/main/CHANGELOG.md", "license": "MIT", "category": "process", "effect": "read-write", "requires": { "speckit_version": ">=1.0.0" }, "provides": { "commands": 3, "hooks": 7 }, "tags": ["security", "threat-modeling", "llm", "agentic", "traceability"], "verified": false, "downloads": 0, "stars": 0, "created_at": "2026-09-21T00:00:00Z", "updated_at": "2026-09-21T00:00:00Z" } }Additional Context
ThreatSpec is not another one-shot threat-report command. It maintains a machine-readable threat model with typed cross-references across the whole lifecycle, so a threat can be traced to a mitigation, a requirement, a task, a test, and a recorded verdict. Structural work (schema, references, coverage, drift, severity) runs deterministically in scripts; the agent is used only for judgment.
The repository also ships two optional companions that install through their own primitives: a
threatspec-sddpreset that appends SR-### awareness to the core tasks, analyze, converge, and checklist commands, and asecure-sddworkflow with review gates.examples/rag-assistant/contains a complete first-pass output generated by the model command from a bare spec, including the rendered threat model, check report, and coverage table, kept valid by the test suite.The extension's own threat model is published at docs/threat-model.md, including the residual risks (indirect prompt injection via artifact content, and the opt-in
verification.test_command).